Oracle Database Server is prone to a remote vulnerability in RDBMS Core.
Credit:
The original article can be found at: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0534
The original article can be found at: http://www.securityfocus.com/bid/53076
Vulnerable Systems:
* Oracle Oracle11g Standard Edition 11.2.0.3
* Oracle Oracle11g Standard Edition 11.2.0.2.0
* Oracle Oracle11g Standard Edition 11.1.0.7 R1
* Oracle Oracle11g Enterprise Edition 11.2 2
* Oracle Oracle11g Enterprise Edition 11.2.0.3
* Oracle Oracle11g Enterprise Edition 11.1.0.7 R1
* Oracle Oracle10g Standard Edition 10.2 .5
* Oracle Oracle10g Standard Edition 10.2 .3 R2
* Oracle Oracle10g Standard Edition 10.2.0.4 R2
* Oracle Oracle10g Personal Edition 10.2 .3 R2
* Oracle Oracle10g Personal Edition 10.2.0.4 R2
* Oracle Oracle10g Enterprise Edition 10.2 .3 R2
* Oracle Oracle10g Enterprise Edition 10.2.0.4 R2
The vulnerability can be exploited over the 'Oracle Net' protocol. For an exploit to succeed, the attacker must have 'Create Session' privileges.
This vulnerability affects the following supported versions:
10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, 11.2.0.3
Vendor Status:
Oracle as issued an update for this vulnerablity
Patch Availability:
http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html
CVE Information:
CVE-2012-0534
Disclosure Timeline:
2012-April-17 Rev 1. Initial Release
Please enable JavaScript to view the comments powered by Disqus.
blog comments powered by